-
May 11th, 2004, 10:29 PM
#1
Identifying a Registry Alteration
I just recently downloaded and ran Registry Editor for the first time, and this message popped up:
An important entry has been ADDED to the registry!
HKEY=HKEY_CLASSES_ROOT
PATH=vbsfile\shell\open\command
NAME=
DATA=%SystemRoot%\System32\WScript.exe "%1"%*
How do I know if this is malicious or something legitimate? Since it was in the System32 directory and evidently affecting an executable for user-run scripts, I didn't want to make any assumptions.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|